Prove Cyber Resilience - Immersive
Immersive One is a SaaS platform designed to measure and enhance cyber resilience. We provide hands-on labs and simulations that build technical muscle memory, moving beyond passive training to provide active performance data. The platform benchmarks workforce readiness against industry frameworks like MITRE ATT&CK and NIST
Features
- Role-specific, practical cybersecurity exercises in live, browser-based environments.
- Scenario-based drills testing decision-making and coordination under high pressure.
- Automated alignment of all exercise outcomes to the ATT&CK framework
- Compare workforce performance against industry peers using live data metrics.
- Sandboxed, on-demand Windows and Linux environments for safe tool experimentation
- Automated generation of customized labs tailored to specific technology stacks
- Personalized training routes that evolve based on individual skill levels.
- Practical labs covering security for AWS, Azure, and Google Cloud.
- Evidence-based dashboards demonstrating cyber resilience and ROI to leadership.
- Secure coding exercises for developers to identify and fix vulnerabilities.
Benefits
- Provide boards with hard data proving technical workforce competency
- Equips teams to neutralize threats faster, lowering potential financial impact
- improvement in response speed and accuracy to justify investment.
- Simplified auditing for DORA, NIS2, ISO 27001, and NIST frameworks.
- Participants gain repeatable experience investigating threats in safe environments.
- Micro-labs allow staff to upskill without disrupting daily operations.
- Pinpoint specific blind spots across teams before attackers exploit them.
- Hands-on practice directly impacts and reduces Mean Time to Respond.
- Compare internal cyber resilience against industry peers and global standards.
- Engages technical staff with high-realism content and clear career pathways.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 6 8 0 4 2 6 6 4 0 0 4 1 7 3
Contact
BROOKCOURT SOLUTIONS LIMITED
Phil Higgins
Telephone: 01737 886111
Email: contact@brookcourtsolutions.com
About the service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Education
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
Immersive One is a cloud-native SaaS platform with the following operational constraints:
Maintenance: Occasional maintenance windows for major updates are scheduled during off-peak hours (usually weekends) to minimize disruption; customers are notified via platform alerts.
Technical Requirements: Users require a stable internet connection and a modern web browser (Edge, Chrome, Firefox, or Safari) with JavaScript and WebSockets enabled.
Hardware: Practical labs require a desktop/laptop with a minimum screen resolution of 1920x1080 for optimal display.
Network: Specific domains and ports (TCP 443, 8100-8199) must be allow-listed for full lab functionality - System requirements
- None
User support
- Email or online ticketing support
- Yes
- Support response times
- Our global support team monitors the ticketing system from 09:00 to 17:00 GMT/BST and EST, Monday through Friday, excluding UK and US holidays. We aim to respond to general queries within one business day. For technical issues, response targets vary by severity: Priority 1 critical incidents receive a response within 2 hours during working or on-call hours, while Priority 2 high-impact issues target a resolution within 0.5 business days. Requests submitted outside these hours or during weekends are addressed the following business day according to priority level.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Immersive offers two primary support levels designed to ensure customers maximize their platform investment:
Standard Support: Included for all customers at no additional cost. It provides 24/7 access to the self-service Support Portal (knowledge base, FAQs) and technical expert assistance during regular business hours (09:00–17:00 GMT/BST) via email and ticketing.
Premium Support: An optional upgrade available for an additional fee, typically agreed upon in the Order Form. It includes priority ticket handling, access to a 24/7 call center for ticket submission, and a dedicated Slack channel for real-time communication with the account team.
Specialist Support Roles
We provide dedicated personnel based on the support tier and solution purchased:
Customer Success Manager (CSM): All customers receive a CSM. Silver tier customers have a designated CSM for the 90-day onboarding period, while Gold and Platinum tiers have a named CSM for the full contract term.
Cyber Resilience Advisor (CRA): Available through Premium Support, acting as a subject matter expert to offer operational experience during events like crisis simulations.
Cyber Workforce Advisor (CWA): Can be assigned to assist in building and tracking long-term resilience plans. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Immersive Labs provides a comprehensive onboarding program tailored to the customer’s purchased tier (Silver, Gold, or Platinum).
Training and Documentation
Online Training: Users have immediate access to a browser-based "Getting Started" path and an extensive Support Portal containing user documentation, FAQs, and video tutorials.
Self-Service Onboarding: A built-in wizard guides administrators through initial setup, including license management and user invitations.
Onsite/Virtual Training: For Gold and Platinum customers, we provide customized workshops and "Platform Champion" training sessions to ensure successful internal adoption.
Dedicated Support
Customer Success Manager (CSM): Every customer is assigned a CSM who leads the 90-day onboarding journey, assisting with technical configuration and setting initial resilience benchmarks.
Implementation Support: We provide specialized guidance for SSO integration and API setup to ensure the platform fits seamlessly into the user’s existing tech stack.
Executive Kick-off: We conduct strategy sessions with leadership to align the platform’s "Prove, Improve, and Report" capabilities with the organization's specific security goals. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
Upon termination of the contract, users can extract their data directly from the Immersive One platform to ensure continuity and record-keeping.
Data Extraction Methods
Self-Service Export: Administrators can use the platform’s reporting interface to export comprehensive performance analytics, user progress, and completion data into CSV or PDF formats at any time.
API Access: Organizations can utilize the GraphQL API to programmatically extract bulk data, including granular lab attempt histories and achievement records, prior to the service end date.
Executive Reporting: Dashboards summarizing organizational resilience and benchmarking against industry standards (e.g., MITRE ATT&CK) can be downloaded as board-ready reports.
Support and Retention
Offboarding Assistance: A dedicated Customer Success Manager (CSM) is available to guide the technical team through the data extraction process to ensure no critical performance metrics are lost.
Data Deletion: Following the extraction period and in accordance with GDPR and our Data Processing Agreement, Immersive Labs will securely delete customer-specific data after a defined retention window, unless otherwise agreed upon in the Order Form. - End-of-contract process
-
At the end of the contract, access to the Immersive One platform is deactivated. Customers are responsible for exporting their data using the self-service CSV/PDF tools or API before the final termination date. Following the contract end, Immersive Labs securely deletes customer data in compliance with GDPR and our Data Processing Agreement, unless a specific retention extension is agreed upon.
Included in the Contract Price:
Full access to the SaaS platform and the purchased content library (Labs, Crisis Sims, or AppSec).
Standard support, including access to the Support Portal, knowledge base, and email ticketing during business hours.
A dedicated Customer Success Manager for the 90-day onboarding journey (Silver) or the full term (Gold/Platinum).
Automatic platform updates and new content releases.
Additional Costs:
Premium Support: Optional upgrades for priority 24/7 ticket handling and dedicated Slack channels.
Advisory Services: On-site facilitation of crisis simulations or bespoke "Cyber Workforce Advisor" consulting.
Custom Content: Development of tailored labs or bespoke training pathways. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The platform is accessed through a browser-based SaaS interface that serves as a central hub for users and administrators. This interface allows users to engage with hands-on labs and simulations while providing administrators with dashboards for real-time performance analytics, benchmarking, and reporting.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Users access the platform through a browser-based SaaS interface, utilizing modern browsers such as Chrome, Firefox, Safari, or Edge. While administrative features and organizational exercises are mobile-optimized, most practical labs require a desktop or laptop with a minimum 1920x1080 resolution. Users can engage in hands-on labs, simulations, and real-time benchmarking but cannot use screen readers or keyboard-only navigation in certain interactive lab environments due to RDP-based virtualization. Admins can manage licenses, resend invitations, and generate performance reports directly within the interface.
- Accessibility testing
-
Immersive Labs conducts regular interface testing to ensure accessibility for all users, guided by WCAG 2.2 Level AA standards and ISO 30071-1.
We employ third-party experts to perform comprehensive accessibility audits on our platform’s key pages and user flows. This testing involves representative assistive technologies commonly used by our audience to identify and mitigate barriers. As a result of these tests, we have obtained a Voluntary Product Accessibility Template (VPAT), which documents our current status and helps prioritize continuous improvements.
Current initiatives include:
Back-Catalogue Conversion: We are transitioning "Theory" labs into a new accessible format specifically built and tested for compatibility with screen readers and keyboard-only navigation, with completion targeted for 2025.
Content Prioritization: Workforce security content has been reviewed and improved to ensure accessibility for the widest possible audience.
Infrastructure Research: We are actively investigating ways to make our RDP-based practical labs more accessible, as the current image-streaming technology is inherently incompatible with screen readers. - API
- Yes
- What users can and can't do using the API
-
Service Setup through the API
Users use the service by generating an API Key and Secret Token) . The key is used to make a POST request to the authentication endpoint, which returns a Bearer Token. This token must be included in the Authorization header of all subsequent API calls to verify the user’s identity and organization.
2. Making Changes through the API
The API V2 enables programmatic changes via Mutations. Users can:
Manage User Access: Use mutations like oidcAttemptLoginRequest to handle and approve user session requests.
Update Organization Data: Modify user profile details and synchronize internal identifiers using the externalId field to ensure the platform aligns with internal directory services.
Automate Team Management: Programmatically assign accounts to specific Teams or Collections to scale onboarding and training paths.
3. Limitations
GraphQL Only: The platform does not offer a standard REST (GET/POST/PUT) structure for every resource; all interactions occur through the single GraphQL endpoint.
Token Lifecycle: Authentication tokens are short-lived, expiring after 30 minutes, requiring automated scripts to include token-refresh logic.
Schema Evolution: As API V2 is the actively maintained version, users transitioning from V1 must update their code to match new types, such as the transition from series to collection. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- We employ Resource Isolation and Multi-tenancy to prevent "noisy neighbor" scenarios where user demand impacts another. By enforcing strict per-user quotas and rate limits, we ensure equitable access to shared resources. Horizontal Autoscaling adds capacity as total load increases, while intelligent load balancers redistribute traffic to healthy nodes. Finally, Circuit Breakers isolate localized failures, preventing them from cascading across the system.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Immersive Labs provides comprehensive real-time metrics across two categories. Application Metrics deliver granular visibility into human cyber-capability, including "Resilience Scores," lab completion rates, time-to-completion, and skill-gap analysis mapped to MITRE ATT&CK® and OWASP frameworks. Benchmarking data allows organizations to compare performance against industry peers.
Infrastructure Metrics ensure platform availability and performance, tracking service uptime, API responsiveness, and system latency. While our DevOps team manages underlying cloud health (AWS) to maintain 99.9% availability, customers access high-level service status and usage statistics via the platform dashboard to ensure consistent, reliable access to hands-on learning environments. - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Supplier type
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Immersive
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data directly from the Immersive One platform using self-service reporting tools. Administrators have the capability to download comprehensive performance analytics, user progress, and completion records into CSV or PDF formats at any time. For bulk data requirements or integration with internal systems, organizations can utilize the GraphQL API to programmatically extract granular attempt histories and achievement data. These methods ensure that boards and regulators receive evidence-based readiness reports and that all organizational resilience metrics are preserved for internal record-keeping.
- Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- GraphQL
- SAML XML:
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Immersive targets a minimum platform availability of 99.5% uptime. This objective applies 24 hours a day, 7 days a week, 365 days a year, though it excludes "excusable downtime". Excusable downtime includes factors beyond the company’s reasonable control, such as third-party service failures, force majeure events, unauthorized platform use, or routine scheduled maintenance.
To ensure transparency, uptime is monitored via a third-party company that generates real-time alerts and reports regarding site availability.
Regarding Service Level Agreements (SLAs) for financial remedies:
No Service Credits: The guide explicitly states that Immersive Labs does not offer service credits if availability targets are missed.
Remedies: The primary remedy for technical issues or performance failures is through the customer support and incident resolution process.
Resolution Targets: While not a refund mechanism, the company provides specific resolution targets based on incident priority, such as a 2-hour initial target to resolve "Priority 1" regional outages during working and on-call hours. - Approach to resilience
-
Immersive is designed as a cloud-native software-as-a-service (SaaS) solution to ensure high availability and resilience. The platform is engineered to be available 24/7/365, targeting a minimum uptime of 99.5%.
To maintain this resilience, the service utilizes:
Continuous Monitoring: We use a third-party monitoring service that generates real-time alerts, reports, and dashboards to track platform uptime and identify potential issues immediately.
Incident Management: A tiered response structure (Priority 1–4) ensures that any service degradation is addressed according to its severity, with the highest priority issues receiving on-call support until resolved.
Redundant Architecture: While specific technical details of our datacenter providers (such as AWS or Azure regions) are available upon request to maintain security, our architecture leverages multiple availability zones to prevent single points of failure.
Service Recovery: In the event of a fault, we employ reasonable commercial endeavors to resolve the incident promptly or provide alternative means to achieve the desired performance. - Outage reporting
-
Immersive monitors platform uptime using a third-party company that generates real-time alerts and reports. Outages and service status are communicated through the following channels:
Public/Customer Dashboards: The third-party monitoring system generates dashboards for platform uptime that provide visibility into service availability.
Email Alerts: Automated alerts are generated in the event the site becomes unavailable. Additionally, customers can be informed of platform changes or news via email updates through the Subscription Center.
Platform Notifications: Customers are informed of upcoming changes and can view status updates directly via notifications within the web application.
In the event of a fault, users are encouraged to report issues via the online support portal, email, or telephone.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Our incident management process follows NIST guidelines through four phases: Plan/Prepare, Detect, Respond, and Recover. We use pre-defined playbooks from NCSC and NIST for common attacks like phishing, malware, and DDoS. Users and staff report incidents via email, Slack, or telephone to the Risk, Security, and Compliance Team. For every incident, we create a Jira ticket containing a timeline, decision justifications, and lessons identified. Detailed reports for critical incidents are stored securely, and Post-Incident Reviews are conducted to capture and implement required changes.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Our security governance follows a data-driven approach that integrates leadership and strategy with broader business objectives. We utilize a specialized framework to ensure board-level involvement in managing cybersecurity risks and aligning workforce capabilities with industry standards like NIST and MITRE ATT&CK. By leveraging the Resilience Score, we provide quantified evidence of organizational readiness and compliance. This structure ensures that security is not just a technical function but a core component of enterprise risk oversight and strategic decision-making.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We manage the lifecycle of service components through a secure software development lifecycle (SDLC) that integrates tracking and oversight at every stage. Components are monitored from inception to decommissioning, with automated tools visualizing telemetry to understand where vulnerabilities may occur. All changes undergo a formal assessment process where our Security Guild and dedicated teams evaluate potential security impacts. This include peer code reviews and testing to ensure changes do not result in material degradation of performance or accessibility.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Threat Assessment
Vulnerabilities are triaged using CVSS 3.1 to determine severity based on metrics like attack vector, complexity, and impact. Each ticket is assessed by a Security Expert and reviewed in weekly calls with platform specialists to ensure accurate prioritization.
Remediation follows strict SLAs based on the CVSS score:
Critical (9.0+): 7 days.
High (7.0–8.9): 14 days.
Medium (4.0–6.9): 45 days.
Low (<=3.9): 90 days.
We gather intelligence from channels:
External: HackerOne bug bounty program, CVE publications, threat feeds, and independent penetration tests.
Internal: Automated vulnerability scans, security audits, and continuous threat research by our internal Cyber team. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We identify compromises through 24/7 automated monitoring, third-party uptime tracking, and intelligence from the HackerOne bug bounty program. When a potential threat is detected, it is triaged via a dedicated Jira board where Security Experts assign a CVSS score to determine the remediation priority. Response follows a tiered structure: Critical "Priority 1" platform outages trigger immediate, on-call support until resolved, while critical vulnerabilities (CVSS >9.0) require remediation within 7 days. High-severity vulnerabilities are addressed within 14 days, ensuring swift mitigation of potential security impacts.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Our incident management process follows NIST guidelines through four phases: Plan/Prepare, Detect, Respond, and Recover. We use pre-defined playbooks from NCSC and NIST for common attacks like phishing, malware, and DDoS. Users and staff report incidents via email, Slack, or telephone to the Risk, Security, and Compliance Team. For every incident, we create a Jira ticket containing a timeline, decision justifications, and lessons identified. Detailed reports for critical incidents are stored securely, and Post-Incident Reviews are conducted to capture and implement required changes.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 1.5%
- Between £500,001 and £1,000,000
- 1.75%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 2.5%
- Over £5,000,001
- 3%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- URS Holidings
- ISO/IEC 27001 accreditation date
- Monday 3 November 2025
- What the ISO/IEC 27001 doesn’t cover
- ISO Certificate covers IT Solutions, Management Consultancy and Integration Services
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- URS Holidings
- ISO 9001 accreditation date
- Saturday 12 October 2024
- What the ISO 9001 doesn’t cover
- ISO Certificate covers IT Solutions, Management Consultancy and Integration Services
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- B1696668-7af9-4f0d-b3b7-34fc20cfc861
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- 0199f451-3f84-44cb-bb20-75e29b818ffe
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
- Structuring of the supply chain selection process to ensure fairness (e.g. anti-corruption) and encourages participation by a diverse range of businesses, including with regard to new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutual
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Collaborating with anchor institutions and community groups to make facilities available for education, training or community events
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
- Mission: Break down barriers to opportunity
-
By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
- Mission: Build an NHS fit for the future
-
That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition